Anonymous
2026-09-20 08:37:53
(1 day ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-19 22:47:11
(1 day ago)
(mod_security-custom) mod_security (id:210801) triggered by 151.244.232.21 (DE/Germany/Hesse/Frankfu ...
show more
(mod_security-custom) mod_security (id:210801) triggered by 151.244.232.21 (DE/Germany/Hesse/Frankfurt am Main/-/[AS44486 SYNLINQ synlinq.de]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-19 14:00:41
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 10:00:37.805609 2026] [security2:error] [pid 14564:tid 14564] [client 151.244.232.21:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:user-agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.socialstudiesforkids.com|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.socialstudiesforkids.com"] [uri "/"] [unique_id "aq6VhdbrJRaPiyAv1k-CHAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 13:44:15
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 09:44:10.046742 2026] [security2:error] [pid 9402:tid 9402] [client 151.244.232.21:56464] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.mikeziegler.com|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.mikeziegler.com"] [uri "/"] [unique_id "aq6RqhlRY3a7ruogFcy9hAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
Michael McCarthy
2026-09-19 12:37:58
(2 days ago)
Web Spam
🇮🇹
CoreTech srl
2026-09-19 10:33:56
(2 days ago)
cloudlinux2 fail2ban: 2026-09-19 12:30:13,322 fail2ban.filter [1813]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-19 12:30:13,322 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 196.238.101.18 - 2026-09-19 12:30:13cloudlinux2 fail2ban: 2026-09-19 12:30:43,021 fail2ban.actions [1813]: NOTICE [plesk-modsecurity] Unban 47.31.76.79cloudlinux2 fail2ban: 2026-09-19 12:30:40,566 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 103.25.81.45 - 2026-09-19 12:30:40cloudlinux2 fail2ban: 2026-09-19 12:30:50,559 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 151.244.232.21 - 2026-09-19 12:30:50cloudlinux2 fail2ban: 2026-09-19 12:31:17,161 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 196.238.101.18 - 2026-09-19 12:31:17cloudlinux2 fail2ban: 2026-09-19 12:31:49,115 fail2ban.actions [1813]: NOTICE [plesk-modsecurity] Ban 196.238.101.18cloudlinux2 fail2ban: 2026-09-19 12:31:49,058 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 196.238.101.18 - 2026-09-19 12:31:49cloudlinux2 fail2ban: 2026-09-19 12:31:
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-19 08:48:07
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 04:48:01.917231 2026] [security2:error] [pid 6809:tid 6809] [client 151.244.232.21:54559] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.revelatorium.com|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.revelatorium.com"] [uri "/"] [unique_id "aq5MQT7vDBR56231pFkDrAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 08:24:48
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 04:24:43.145242 2026] [security2:error] [pid 30113:tid 30113] [client 151.244.232.21:55808] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||salernospizza.com|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "salernospizza.com"] [uri "/"] [unique_id "aq5GyxXUikchSqy-1hAADgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 07:25:42
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 03:25:34.999671 2026] [security2:error] [pid 8635:tid 8635] [client 151.244.232.21:57025] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.joshuashands.org|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.joshuashands.org"] [uri "/"] [unique_id "aq447v5CZh8nedZrbnZxDQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 06:19:36
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 02:19:29.892507 2026] [security2:error] [pid 17332:tid 17332] [client 151.244.232.21:51096] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||rnance.com|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "rnance.com"] [uri "/"] [unique_id "aq4pce41bpljSlVDd2SZWAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 05:45:56
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 01:45:49.781314 2026] [security2:error] [pid 17262:tid 17292] [client 151.244.232.21:64699] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.gotlib.net|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.gotlib.net"] [uri "/"] [unique_id "aq4hjdRPztUmZsk4-uAkWQAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-19 05:18:00
(2 days ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-19 05:05:08
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 01:05:01.488111 2026] [security2:error] [pid 3837:tid 3837] [client 151.244.232.21:56878] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.tonytremblayauthor.com|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.tonytremblayauthor.com"] [uri "/"] [unique_id "aq4X_TUPXQsLQAb3uNqXFgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 04:44:37
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 00:44:30.814768 2026] [security2:error] [pid 11643:tid 11643] [client 151.244.232.21:56113] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.travelwithjenniferb.com|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.travelwithjenniferb.com"] [uri "/"] [unique_id "aq4TLh7SKf_uouUznqsi9AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 04:17:56
(2 days ago)
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 151.244.232.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 00:17:49.315950 2026] [security2:error] [pid 8806:tid 8806] [client 151.244.232.21:64689] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.bikiniadvice.com|F|2"] [data "mozilla/5.0 (compatible; warc-grabber-livecheck/1.0)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.bikiniadvice.com"] [uri "/"] [unique_id "aq4M7Sg7Hdpd_-G7g-HAWAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack